Live data from Hacker News

Black Hat: GDPR privacy law exploited to reveal personal data

bbc.co.uk

221–230 of 239 posts

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#221
post #95
post #23

Earlier quoted context omitted.

Agreed. I hope any jury would nullify such a law. AKA "perverse verdict" in the UK?

Juries can't nullifiy laws. They can nullify verdicts.

Good point.

>A jury verdict that is contrary to the letter of the law pertains only to the particular case before it. However, if a pattern of acquittals develops in response to repeated attempts to prosecute a particular offence, this can have the de facto effect of invalidating the law.

-Wikipedia

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#222

Earlier quoted context omitted.

Ugh, my Austrian bank is currently trying to force me into using a system like this. The "standard" way is via an Android or iOS app, the "alternative" is via a smartcard reader thing that seems to work with Windows only. They claim that this is mandatory due to some EU regulation, but they conveniently forget to say what regulation that is supposed to be.

It's the Payment Services Directive (PSD2). Username+PW is obsolete and insecure at least 20 years now.

> It's the Payment Services Directive (PSD2). Username+PW is obsolete and insecure at least 20 years now.

That does not imply that banks must implement 2FA with their proprietary applications.

Banks could just implement TOTP (Time-based One-time Passwords, RFC 6238) or HOTP (HMAC-based One-time Passwords, RFC 4226) and let me choose how I generate my OTP. For example with an hardware OTP generator or an open source application.

Most banks are using PSD2 as a occasion to force their privacy-invading apps on their users.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#223
post #160

Earlier quoted context omitted.

But then "just don't keep the data" is not an effective response to these attacks of requesting someone else's data.

Yes, it requires people to be trained in this area to make these judgements ... imagine that!

How well is that turning out? You can't rely on people to get it right 100% of the time. I definitely wouldn't.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#224
post #160

Earlier quoted context omitted.

Yes, it requires people to be trained in this area to make these judgements ... imagine that!

How well is that turning out? You can't rely on people to get it right 100% of the time. I definitely wouldn't.

I signed up to a crypto exchange, then I requested removal of my account and data and they said they cannot delete my data. Guess what? I had zero transactions, the account was new, etc. They are legally obliged to keep almost nothing for 7 years. How lovely. At least they were open about it, right? Some will just tell you they deleted your account when in fact it was just a soft delete. Screw these places. I, for one, hope that Bisq will become popular.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#225

Earlier quoted context omitted.

> You can get the key embedded on a smartcard, but it's still coupled to their proprietary driver (which only works on Windows or macOS, of course). Maybe it is different where you live but the standalone hardware key I mention is standalone: You open the website, enter your national id, find your token generator, enter pin code for hardware token, read your token, type it into the bank web site, and enter your passw…

> Maybe it is different where you live but the standalone hardware key I mention is standalone: You open the website, enter your national id, find your token generator, enter pin code for hardware token, read your token, type it into the bank web site, and enter your password ib a different field. That sounds completely different. "BankID På Kort" is basically the same experience as using an OpenPGP smartcard: it pro…

> That sounds completely different. "BankID På Kort" is basically the same experience as using an OpenPGP smartcard: it prompts you to insert the card, enter your PIN, and everything else is handled in the background.

Agreed, sounds completely different. We had some smartcard id system here as well, but last time I saw any of that in practical use for banking was 10 or so years ago, and even then it was standalone (battery driven, small enough to fit in my pocket) and not dependent on a PC with proprietary OS.

> Many banks here (and at least Nordea used the CC for this) also support manual challenge/response auth like you describe, but this is unrelated to BankID and seems to generally be considered deprecated.

I see. Around here this is official from BankID and it seems you need a "proper" physical BankID to even log into hour bank to issue a mobile BankID[0].

> From what I can tell, Swedish and Norwegian BankID are completely separate. NorBankID seems to be operated by Vipps [...] and have existed since 2004, while SweBankID is owned by Finansiell ID-Teknik[...]since 2002.

The Vipps situation might be a bit confusing, Vipps wasnt created until a few years ago but it is more or less universally loved by everyone, so it seems they have used that name to cover everything.

>They also don't share the logo, or seem to have any ties between their websites.

You are right. Good point. I'm not sure anymore that they are related.

> Government services usually also support Telia's NetID (which is similar to BankID På Kort, but at least seems to provide a Linux driver).

Around here the government have their own (MinID), but yu can also use buypass, COMMFIDES, or Norwegian BankID. I never see anyone using anything except MinID or BankID though.

> However, BankID is also starting to become popular for services that would otherwise have been fine with plain old username/password authentication, rather than implementing U2F or TOTP. These services usually don't put a lot of thought into their implementation, and don't tend to implement alternative auth methods. Older services will support username/password for existing users, but expect it to be considered deprecated. Examples of this category would be Hallon (mobile network), Hemfrid (home cleaning service), or Kivra (crappy email without the federation).

With a broken system that by design isn't cross platform like you describe this seems like a bad idea, yes.

>Don't let decent be the enemy of good.

Agree. That said I find the Norwegian implementation is good now after they got rid of the applets a few years ago, and even back then I was able to somehow get it to work - and it was about as broken on Windows as well ;-)

Today it Just Works across alll devices I use for work as well as at home: Linux laptops, Windows laptops, iPad, Android phone and probably whatever else as long as it has a any modern browser (I use FF mostly, but it seems to work in everything from IE and Edge to Opera and Chrome).

Summarized I guess the Norwegian BankID is good, and the Swedish one is bad?

[0]: https://www.bankid.no/privat/kom-i-gang/

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#226
post #160

Earlier quoted context omitted.

Yes, it requires people to be trained in this area to make these judgements ... imagine that!

How well is that turning out? You can't rely on people to get it right 100% of the time. I definitely wouldn't.

You don’t have to get it right 100% of the time, you just have to look like you’re trying.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#227
post #216

Earlier quoted context omitted.

I've heard that in Japan, stamping with your personal stamp is accepted (and perhaps sometimes even required?). They have made electronic gadgets that store their stamps as images so that they can directly sign (stamp) an electronic document (using a specific input device). I think we should have something like this, but with a personal certificate instead of an image. Of course I guess it requires some logistics (lo…

Isn’t this equivalent to stamping PDFs with your signature like we do elsewhere ? Also the stamp has to be registered to have legal value, which makes it tough to change. But your idea of signing with the result of some personal certificate is very nice. It can be checked by crypto, different everytime, and wouldn’t matter how it is signed, if it’s easy to reproduce the content etc..

> Also the stamp has to be registered to have legal value, which makes it tough to change.

This is not actually true. Some stamps need to be registered (for example the stamp for corporation), but personal stamps for most applications don't need to be registered -- even for bank accounts. I have several and I'm always forgetting which one I used for my different bank accounts :-P.

One of the strange things about Japanese stamps is that if you let someone have your stamp, then it is considered that you have given them permission to do whatever they want with that stamp. The very fact that they have the stamp means that they are authorised. I got very angry at my previous employer (the government, no less) when my contract was over. They demanded that I give them my stamp I had used for stamping my time card. It happened to be the one I used for my bank account too (because I was clueless at the time!) It took me a couple of months to work around that. If you are ever working in Japan, treat your hanko (stamps) exactly the same way you would treat your encryption keys: use a different one for each application if possible.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#228
post #222

Earlier quoted context omitted.

It's the Payment Services Directive (PSD2). Username+PW is obsolete and insecure at least 20 years now.

> It's the Payment Services Directive (PSD2). Username+PW is obsolete and insecure at least 20 years now. That does not imply that banks must implement 2FA with their proprietary applications. Banks could just implement TOTP (Time-based One-time Passwords, RFC 6238) or HOTP (HMAC-based One-time Passwords, RFC 4226) and let me choose how I generate my OTP. For example with an hardware OTP generator or an open source a…

Absolutely not, I heavily dislike SmartID and similar proprietary spyware as well. A TOTP HW token would be in my opinion more secure. The reason banks use it though is the convenience, having some identity tied to the apps is just a bonus for them.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#229

Earlier quoted context omitted.

In my country (Oz) we had a referendum a few decades back about a national ID card, which failed to pass. I for one am against any form of centralised ID system. The basic premise (of the time) was, "if you want to know me, here I am". The government department of Birth, Deaths and Marriages goes to some lengths to ensure that these 3 things are not tied to any one number. Ironically, the government got what it wante…

Any centralized identity system solves a problem we don't have. It doesn't simply serve to identify a person. It serves to aggregate an identity and tie together extremely disparate and unrelated data. It enables a data leak or abuse to not just compromise one service, but all of them at once. If there is a leak of data from, say, a dating site that involves dumping the public keys of the users alongside the user act…

> Any centralized identity system solves a problem we don't have.

You already have one, SSN and similar absolutely count and allow aggregate different data. Not to mention that you're absolutely forgetting about the fact that humans don't have a lot of entropy, k-anonymous data is not what we have by-default. You are wrong about a centralized system "providing a way to aggregate data" it just makes it easier. I live in a country that actually gives citizens access to a centralized identity system and I'd say it has solved much more than you're giving credit for.

Re: Black Hat: GDPR privacy law exploited to reveal personal data

#230
Yes. This just shows the problem that was already there. The GDPR is fundamentally a thing about having the responsibility to handle people's data properly The companies that failed, obviously cannot handle the responsibility of managing personal data without it getting into the hands of the wrong people and they shouldn't have had it in the first place.

It's much harder to test but this is a good indicator that they probably also don't have controls to manage employee access.

Post reply on HN